## What changed
- Add the default-off `windows_sandbox_service` feature and expose it through
app-server experimental feature enablement.
- When enabled, attempt service provisioning during elevated Windows sandbox
setup, using the effective network proxy ports and listener roles. Continue
through the existing setup path when the service is unavailable or the
configuration is unsupported.
- Report unsupported Codex home drives as service unavailability so the client
can fall back to the elevated helper.
## Testing
- Add a Windows-only unit test covering HTTP and SOCKS listener derivation from
the effective proxy configuration.
GitOrigin-RevId: 40b119cf51f84e5d0e94d6a0a8d5b506d1123526